INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Meta's Instagram Password Reset System Crashes
| 2026-01-11 23:43 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A series of high-profile cyberattacks occurred in January 2026, with Meta's Instagram service being targeted by third-party attackers who exploited a vulnerability allowing them to generate password reset emails. The attack resulted in the theft of sensitive information from approximately 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more. This was likely facilitated by an API leak detected in 2024, which exposed user data on notorious data leak site BreachForums. Meanwhile, a ransomware attack on gas station chain Handi revealed the exposure of customer data from around 377,082 sets of customers, including names, social security numbers, contact information, and driver's license numbers. The attackers exploited vulnerabilities in Veeam, a popular data management and backup vendor, which was patched by the company last week after four critical flaws were discovered, one of which scored a 9.0 on the CVSS scale.
Technical Mitigations AI-generated
• Patch CVE-2025-59470 in Veeam Backup and Tape Operator accounts to prevent RCE attacks.
• Block or hunt for dark web posts offering bribes to insiders, as reported by Nord Stellar.
• Monitor for API leaks like the one detected in 2024 that may expose user data.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-59470CVE-2025-59470
Target & Sectors
Global Scope
educationeducation
technologytechnology
Incident Timeline
2026/01/11
Threat actors obtained user credentials via infostealer malware to log in to ownCloud accounts without MFA, exposing sensitive information of 17.5 million Instagram users.
Click on any entity below to view its context and source!
victims
17 Instagram users
The Register
understands that Malwarebytes was probably referring to a dataset posted to notorious data leak site BreachForums, where a user posted a dump of 17-million-plus Instagram users’ personal information and claimed they were the result of…
infrastructure
17.5
Last Friday, security software vendor Malwarebytes
claimed
“Cybercriminals stole the sensitive information of 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more.”
Tactical Metrics
Metrics
victims
17,000,000
Instagram Users
Click for context!
The Register
understands that Malwarebytes was probably referring to a dataset posted to notorious data leak site BreachForums, where a user posted a dump of 17-million-plus Instagram users’ personal information and claimed they were the result of…
Metrics
infrastructure
17.5
Software Version
Last Friday, security software vendor Malwarebytes
claimed
“Cybercriminals stole the sensitive information of 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more.”
Intelligence Sources
The Register - Cybercrime
2026-01-11
Meta admits to Instagram password reset mess, denies data leak
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:52
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
Gulshan Management Services
entity
4x
timeline
Temporal Reference
2026-01-04
date
3x
tactic
Cyber Operation Type
Ransomware
tactic
2x
source region
Origin Country
United States
country
Contextual Telemetry
Context Block
12 METRICS
general metric
Gas Stations
150
gas stations
industry
Targeted Sector
Education
sector
attribution
Attributing Entity
the Department for Education
authority
victims
Instagram Users
17,000,000
instagram users
vulnerability
CVSS Score
9
score
general metric
Vulnerability
9
vulnerability
general metric
Sets
377,082
sets
infrastructure
Software Version
17.5
version
general metric
Instagram Accounts
17,500,000
instagram accounts
vulnerability
Exploited CVE
CVE-2025-59470
cve
tactic
MITRE ATT&CK Technique
T1556.006 - Multi-Factor Authentication
technique
general metric
Different Global Companies
50
different global companies
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.